Executive brief
TrueConf Client, a video conferencing and collaboration tool, contains a security flaw in how it handles software updates. The application fails to verify the digital signature or integrity of update files before installing them. An attacker who can intercept or manipulate the network traffic between the user and the update server can replace a legitimate update with malicious software. This could allow an attacker to take full control of the user's computer, potentially leading to data theft or unauthorized access to corporate communications.
Technical details
TrueConf Client is vulnerable to a 'Download of Code Without Integrity Check' (CWE-494). The application downloads update packages but fails to perform cryptographic verification or signature checks before execution. An attacker positioned on the local network or update delivery path can perform a man-in-the-middle (MitM) attack to substitute the legitimate update with a malicious payload. Successful exploitation results in arbitrary code execution in the context of the updater process or the logged-in user. This vulnerability has been observed in active exploitation in the wild. The issue is addressed in TrueConf Client version 8.5.3.884 and later.
Affected products
- TrueConf TrueConf Client versions up to (excluding) 8.5.3.884
Timeline
- 2026-03-30: disclosed: Initial disclosure by Check Point Software Technologies Ltd.
- 2026-03-31: exploited: Reported as being used in 0-day exploitation against Southeast Asian government targets.
- 2026-04-02: kev added: Added to CISA Known Exploited Vulnerabilities (KEV) catalog.
- 2026-04-03: patched: NIST analysis confirms patch in version 8.5.3.884.